Communications_Suggestions_by_Press_Office_Director.docx https://www.virustotal.com/#/file/55e2699721379352b0be2ea6b1c71257342d07efbe78c84d7257497f8f75e967/detection … #DDEAUTO #malware #phishing #powershell #infosec
-
Show this thread
-
This Tweet is unavailable.
-
Replying to @ImPureMotion
Thoughts on targeting or who would be behind this?
1 reply 0 retweets 0 likes -
This Tweet is unavailable.
-
Replying to @ImPureMotion
Great find! Any thoughts
@VK_Intel@James_inthe_box@GossiTheDog@ItsReallyNick@bartblaze3 replies 0 retweets 1 like -
Replying to @securitydoggo @ImPureMotion and
"who would be behind this?" We're tracking it, but it's best practice to blame ITW ObfuscatedEmpire on
@cobbr_io &@danielhbohannon
2 replies 0 retweets 6 likes -
Replying to @ItsReallyNick @ImPureMotion and
Nah I just copy-paste code, please direct all blame towards
@danielhbohannon
1 reply 0 retweets 5 likes -
Replying to @cobbr_io @ItsReallyNick and
Not so fast, buddy. Now that you're maintaining Invoke-Obfuscation you get equal blame. It was in the fine print but was obfuscated so...
2 replies 0 retweets 6 likes -
Replying to @danielhbohannon @cobbr_io and
One member of this dynamic duo has atoned for his sins :)
2 replies 0 retweets 5 likes -
Replying to @Lee_Holmes @danielhbohannon and
Hey now, Daniel was given a year of preaching obfuscation. Give me some time :)
1 reply 0 retweets 1 like
No worries, we'll be mostly blaming Daniel for now ;) Invoke-Obfuscation is definitely gaining popularity among actors.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.